logo

Pwning Malware with Ninjas and Unicorns

ID: a26452d3-6a14-5ca4-b951-87aa68065d57

STIX ID: report--a26452d3-6a14-5ca4-b951-87aa68065d57

Feed Name: LevelBlue SpiderLabs Blog

Threat Score
70/100

Date Published: 2026-02-16

Date Updated: 2026-04-28

Author: Cade Wriglesworth

...
...

This report documents a DFIR-driven reverse engineering effort against a packed ELF64 Linux malware (likely a new SysUpdate variant). The analyst details static and dynamic analysis that identified custom key-generation and an XOR-based encryption/decryption routine, and demonstrates building Unicorn Engine (Rust) emulators and Binary Ninja/GDB-assisted memory carving to generate the malware's key material and decrypt intercepted C2 traffic.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.